Operating System - HP-UX
1753705 Members
4843 Online
108799 Solutions
New Discussion юеВ

No /etc/default/security PHCO_24839 and man page incorrect

 
Jim Krol
Advisor

No /etc/default/security PHCO_24839 and man page incorrect

I have patch PHCO_24839 installed on my HP-UX 11.11 server. According to the Patch Release Notes, the following options have been added for the /etc/default/security file:
PASSWORD_MIN_UPPER_CASE_CHARS
PASSWORD_MIN_LOWER_CASE_CHARS
PASSWORD_MIN_DIGIT_CHARS
PASSWORD_MIN_SPECIAL_CHARS

1) I can't find the file /etc/default/security (shouldn't there be a template file someplace?)
2) the man page for security does NOT show these additional features

Is there some better documentation on the security file and how to use it? Or am I missing some other patch?

Thanks :)
5 REPLIES 5
James R. Ferguson
Acclaimed Contributor

Re: No /etc/default/security PHCO_24839 and man page incorrect

Hi:

I believe that you are responsible for creating this file yourself. The patch notes for PHCO_24839 document the syntax for the new features above. The man pages for 'security(4)' note that "If any parameter is not defined or is commented out in this file, the default behavior...will apply.". I assume that an absent file constitutes an undefined condition.

Regards!

...JRF...

Ken Hubnik_2
Honored Contributor

Re: No /etc/default/security PHCO_24839 and man page incorrect

We just implemented this on all our unix servers and yes you have to create the file yourself or make your on template to copy to all the servers with the options you want.
Jim Krol
Advisor

Re: No /etc/default/security PHCO_24839 and man page incorrect

Thanks...will the man page for security be updated to show these new features?

Also, what if this HP-UX 11.11 server is an NIS master? Will these features apply to the NIS password file?

Thanks :)
James R. Ferguson
Acclaimed Contributor

Re: No /etc/default/security PHCO_24839 and man page incorrect

Hi (again):

With regard to the question of whether or not updated 'man' pages will appear with this patch, it appears not. If you examine the patch test, you will find that there is no mention of man pages (i.e. files in '/usr/share/man/') in the "Patch Files" section of the notes. As I already indicated, however, the patch text *does* document the new fields for you.

With regard to whether these features apply to the NIS file, I believe the answer is affirmative.

Regards!

...JRF...
Bill Hassell
Honored Contributor

Re: No /etc/default/security PHCO_24839 and man page incorrect

The man pages are a work in progress. The man page for 'security' exists only in 11.11 but applies to 11.0 (if you have the latest libpam patches for 11.0). The combination of the man page for 11.11 plus all the comments in the patch README will give you the details for the /etc/default/security file.

Note: spelling counts! Options in the security file are just ignored if they aren't correct.


Bill Hassell, sysadmin